Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-15961

Опубликовано: 27 июн. 2026
Источник: fstec
CVSS3: 6.1
CVSS2: 5.4
EPSS Низкий

Описание

Уязвимость библиотеки упрощения упаковки проектов setuptools связана с неправильной обработкой Unicode символов. Эксплуатация уязвимости может позволить нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

Вендор

ООО «Ред Софт»
Red Hat, Inc.
Python Software Foundation

Наименование ПО

РЕД ОС
Red Hat Hardened Images
setuptools

Версия ПО

7.3 (РЕД ОС)
8.0 (РЕД ОС)
- (Red Hat Hardened Images)
до 83.0.0 (setuptools)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 7.3
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 5,4)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 6,1)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для setuptools:
https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2026-3447.yaml
https://github.com/pypa/setuptools
https://github.com/pypa/setuptools/commit/dd9f436a36486b4cb8a4c70a2321548b0be09b8f
https://github.com/pypa/setuptools/releases/tag/v83.0.0
https://github.com/pypa/setuptools/security/advisories/GHSA-h35f-9h28-mq5c
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/CVE-2026-59890
Для Ред ОС:
http://repo.red-soft.ru/redos/7.3c/x86_64/updates/
http://repo.red-soft.ru/redos/8.0/x86_64/updates/

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 32%
0.00405
Низкий

6.1 Medium

CVSS3

5.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.1
ubuntu
3 месяца назад

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.

CVSS3: 6.1
redhat
3 месяца назад

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.

CVSS3: 6.1
nvd
3 месяца назад

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so on macOS APFS or HFS+ an NFD file name could bypass an NFC exclusion rule and be packed into a source distribution. This issue is fixed in version 83.0.0.

CVSS3: 6.1
msrc
3 месяца назад

setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

CVSS3: 6.1
debian
3 месяца назад

setuptools is a package that allows users to download, build, install, ...

EPSS

Процентиль: 32%
0.00405
Низкий

6.1 Medium

CVSS3

5.4 Medium

CVSS2